Employee Portal Vulnerability

SteveOSteveO Member Posts: 164
edited 2006-04-04 in Navision e-Commerce
Hello to everyone,

Just thought I'd let you all in on a recent discovery I made with regards to Employee Portal.

When the webparts are writing out data from Navision they process html tags, and do not write them out as plain text. This unfortunately could allow malicious scripts to be run.

eg. If someone enters
<h1>Some Name</h1>

in the customer name in the customer card webpart then the Customer List will show Some Name formatted with the h1 tags.

How does this get reported to Microsoft so that it can be corrected?
This isn't a signature, I type this at the bottom of every message

Comments

  • kinekine Member Posts: 12,562
    If you are partner, you can report it through service incident. If you are not partner, let me know and I will report it...
    Kamil Sacek
    MVP - Dynamics NAV
    My BLOG
    NAVERTICA a.s.
  • SteveOSteveO Member Posts: 164
    Ok thanks, yup we are a Partner so I'll get it logged.
    This isn't a signature, I type this at the bottom of every message
Sign In or Register to comment.